Research questionHow can AI agent harnesses prevent trusted plugin updates from triggering host-privileged attacker commands through lifecycle hooks?Lifecycle hooks can bind shell commands to routine agent events and execute them with host privileges, including at times the model may not observe. A malicious update can therefore transform benign plugin configuration into host-side behavior without obvious agent involvement.